Permissions, Privileges, and Access Controls in OpenSSH - CVE-2015-5600
Published: August 3, 2015 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list.
Affected software
Amazon Linux AMI
Fedora
Dell Secure Connect Gateway
openssh (Alpine package)
openssh
Integrated Management Module II (IMM2)
3PAR OS
How to mitigate CVE-2015-5600
Dell Secure Connect Gateway - update to 5.14.00.10
openssh (Alpine package) - update to 6.4_p1-r3
Integrated Management Module II (IMM2) - update to 1AOO68L — 5.20
3PAR OS - addressed in versions 3.2.1 MU5, 3.2.2 MU3
openssh - addressed in versions 6.6.1p1-14.fc21, 6.6.1p1-16.fc21, 6.9p1-3.fc22
External References
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c.diff?r1=1.42&r2=1.43&f=h
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10697
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165170.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162955.html
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00017.html
- http://openwall.com/lists/oss-security/2015/07/23/4
- http://rhn.redhat.com/errata/RHSA-2016-0466.html
- http://seclists.org/fulldisclosure/2015/Jul/92
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/bid/75990
- http://www.securityfocus.com/bid/91787
- http://www.securityfocus.com/bid/92012
- http://www.securitytracker.com/id/1032988
- http://www.ubuntu.com/usn/USN-2710-1
- http://www.ubuntu.com/usn/USN-2710-2
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05128992
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667
- https://kc.mcafee.com/corporate/index?page=content&id=SB10136
- https://kc.mcafee.com/corporate/index?page=content&id=SB10157
- https://lists.debian.org/debian-lts-announce/2018/09/msg00010.html
- https://security.gentoo.org/glsa/201512-04
- https://security.netapp.com/advisory/ntap-20151106-0001/
- https://support.apple.com/kb/HT205031
Related Security Bulletins
- Permissions, Privileges, and Access Controls in OpenSSH
- Permissions, Privileges, and Access Controls in openssh (Alpine package)
- Amazon Linux AMI update for openssh
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Permissions, privileges, and access controls in HPE 3PAR OS running OpenSSH
- Multiple vulnerabilities in IBM Integrated Management Module II (IMM2)
- Fedora 22 update for openssh
- Fedora 21 update for openssh
- Fedora 21 update for openssh